The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Security & GRC Decoded
Security & GRC Decoded artwork

“This GRC Space is Hot!” with Varun Gurnaney, Staff Security Engineer at Apple

Security & GRC Decoded · 2025-09-11 · 54 min

0:00--:--

Topics in this episode

Compliance automationAppleGRC engineeringVarun Gurnaneyaudit automation

Episode notes

How does a software engineer become a GRC leader? In this episode of Security & GRC Decoded , host Raj Krishnamurthy welcomes Varun Gurnaney , Staff Security Engineer at Apple . Varun shares his journey from writing janky Python scripts for compliance evidence collection to shaping the discipline of GRC engineering at some of the world’s biggest companies. He discusses the cultural and technical gaps between security, engineering, GRC, and audit - and how automation can bridge them. From building one control really well to proving value through audit automation, Varun lays out why the GRC space is hotter than ever. This conversation is a must-listen for anyone navigating compliance at scale. 5 Key Takeaways Compliance ≠ Security : Passing audits is not enough - engineering-driven GRC is the future. Start Small : Automate one control well to prove value before scaling automation. Bridging Teams : Cultural friction between engineering, security, GRC, and audit is real - empathy and communication reduce the pain. Audit Anxiety : Audit automation is about reducing anxiety and toil as much as passing audits.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Ignite Startups: How Adam Nash Built Daffy Into a $1B Donor-Advised Fund Platform | Ep281Ignite · on Apple87 / 100
  • From Amazon to Arm: The Blueprint for Scaling Tech Giants with Jason ChildSecrets of Rockstar CFOs · on Apple85 / 100
  • You Can't Beat Wise on FX. So Now You Partner With Them | Samarth Bansal, General Manager at Wise PlatformPurpose Driven FinTech · on Compliance automation85 / 100
  • Leadership Lessons from AT&T and e.l.f. Beauty | Kellogg School of Management Marketing Leadership SummitThe CMO Podcast · on Apple80 / 100
  • The Progressive Firm Pod Podcast S2E5: Rolling out tech without rattling clientsAccountingWEB · on Compliance automation76 / 100
  • Practical Strategies for Thriving Amidst Disruption With Chad BlackburnLevelUp Podcast · on Compliance automation75 / 100

More from Security & GRC Decoded

All episodes →
  • The Evolution of Modern GRC ft. James Huang, Head of GRC @ Gong86 / 100
  • The Trust Gap in AI: Why Agents Need a New Certification Model ft Rajiv Dattani & David Meyer @ AIUC76 / 100
  • Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPath88 / 100
  • From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeave96 / 100
  • The GRC Illusion: Why Third-Party Risk Is Still Broken ft Val Dobrushkin, Director of GRC @ Tricentis86 / 100
Explore the best B2B Ops podcasts →
All Security & GRC Decoded episodes →